Description
Vulnerability in Oracle APEX (component: Installation). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle APEX executes to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle APEX accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the Installation component of Oracle APEX, enabling a local attacker with host logon to compromise the APEX instance. Successful exploitation allows all data accessible by the application. This weakness arises from inadequate access control during installation and results in a confidentiality breach. The CVSS score of 5.5 reflects a moderate risk, affecting confidentiality 24.1, 24.2 and 26.1 are affected. All installations of these releases are vulnerable, while earlier and later releases are not listed as impacted.

Affected Systems

Oracle APEX installations running the 24.1, 24.2, or 26.1 releases are affected. Any host a low‑privileged user and runs one of these releases is vulnerable, regardless of administrative separation. Versions earlier than 24.1 or later than 26.1 are not listed as impacted.

Risk and Exploitability

The EPSS score is less than 1%, indicating a low probability of exploitation as of this analysis. The vulnerability is not included in CISA's KEV catalog. The CVSS vector shows the requirement of local access (AV:L) and low authentication (PR:L) with no user interaction, meaning a user who can log on to the host running APEX can exploit it without remote assistance. The impact is confined to confidentiality, with no described integrity or availability effects.

Generated by OpenCVE AI on August 4, 2026 at 03:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch or upgrade Oracle APEX to a non‑affected version, as detailed in Oracle CPU July 2026.
  • Restrict local user access to the host running Oracle APEX by enforcing least‑privilege principles.
  • Disable any installation services or configure the web server to require authentication before installation tasks can be performed.

Generated by OpenCVE AI on August 4, 2026 at 03:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Local Access Vulnerability in Oracle APEX Installation Enables Unauthorized Data Access

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Local Access Vulnerability in Oracle APEX Installation Enables Unauthorized Data Access

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle APEX Installation Vulnerability Enables Local Compromise and Data Exposure
Weaknesses CWE-200

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Oracle APEX Installation Vulnerability Enables Local Compromise and Data Exposure
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle APEX (component: Installation). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle APEX executes to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle APEX accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle apex
CPEs cpe:2.3:a:oracle:apex:24.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:apex:24.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:apex:26.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle apex
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-05T13:48:12.033Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60630

cve-icon Vulnrichment

Updated: 2026-07-27T12:38:47.403Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses